Privacy Policy
Effective Date: October 3, 2026 • Application Version: 0.1.0
Internal Enterprise System — Restricted Access
1 Private & Proprietary Software Notice
Important Notice: SAFA (including the SAFA mobile application, package com.safa.account, and associated web workspace services) is a private, proprietary enterprise accounting and financial ledger software. It is strictly designed for internal operational management and is NOT intended for the general public.
Public user registration is not offered or permitted. Access is exclusively granted to authorized business personnel, operators, and staff members whose accounts have been manually provisioned and verified by the system super-administrator.
2 Information We Collect
In order to provide secure financial accounting, currency conversion, and ledger bookkeeping services, the system processes the following operational information:
- Operator Profile: Name, mobile phone number, email address, role assignment, and administrative access permissions.
- Authentication & Security Tokens: Cryptographic access tokens, refresh tokens, device identifiers, and session validity timestamps.
- Commercial & Accounting Records: Customer details, supplier transactions, currency exchange rates (SAR/BDT), wallet ledgers, expense/income records, and balance entries recorded by authorized operators.
- Operational & Audit Telemetry: Synchronization cursors, record version timestamps, and access audit logs for fraud prevention and financial consistency.
3 Biometric & Device Security
The SAFA mobile application supports optional biometric quick-unlock (fingerprint and face biometric factors) strictly via the Android Operating System's native BiometricPrompt and hardware-backed Android Keystore.
- Zero Biometric Transmission: Raw biometric identifiers (fingerprint scans or facial templates) never leave your physical mobile device and are never sent to, collected by, or stored on our servers.
- Local Unlock Only: Biometrics act strictly as a local unlock factor for the active on-device session.
4 Data Storage & Synchronization
SAFA operates on a high-integrity, local-first architecture:
- Encrypted Local Storage: Operational records are stored locally in an isolated, secure Room/SQLite database on the authorized device to enable continuous offline operations.
- Encrypted Network Transmission: All data synchronization between client devices and the central server is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
- Tenant Isolation: Strict multi-tenant boundaries prevent any cross-account data leakage. Operators only see records associated with their authorized account.
5 No Third-Party Tracking or Data Selling
We maintain strict data privacy standards:
- We do NOT sell, rent, or trade your business, operational, or personal data to third parties under any circumstances.
- We do NOT use third-party advertising SDKs, ad trackers, or behavioural profiling tools in the application or web portal.
- Data is used solely for the legitimate business accounting and management functions requested by authorized operators.
6 Data Retention & Access Revocation
Financial ledger and transaction records are preserved in accordance with enterprise record-keeping and auditing standards. When an operator is deactivated by the administrator:
- All active session tokens are immediately revoked.
- Active synchronization with the server is immediately blocked.
- Local application storage on client devices is securely cleared upon sign-out.
7 Developer & Contact Information
If you have questions regarding this Privacy Policy or system security, contact the system administrator: